Live data from Hacker News

Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

community.rapid7.com

141–150 of 232 posts

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#141
post #65

Earlier quoted context omitted.

I am running out of space because Play Store and Google Framework get bigger and bigger. It fills me with rage how Google actively makes my old phone less capable over time for no benefit to me.

Yeah. I was using a Nexus One for a long time until I had to prune so many apps due to space that it wasn't worth using. I got a new phone, HTC One S (I needed a t-mobile branded phone for wifi calling) with several gigs of system partition space, and now I have to play that game again. I recognize that there are a bunch of features now that I get to enjoy, but now I have to choose which ones I want to keep. When I s…

I'm reinstalling right now to test, it shows as a ~28MB download. I feel pretty confident it's not cached data in my case, as I don't use the Chrome browser on my phone (I prefer Dolphin with gestures & LastPass integration), and on a tablet I only use it for logging into wifi hotspots.

.... And after the reinstall it shows up as 65MB of app.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#142
post #106
post #65

Earlier quoted context omitted.

I am running out of space because Play Store and Google Framework get bigger and bigger. It fills me with rage how Google actively makes my old phone less capable over time for no benefit to me.

Yea, don't they know 128 mb should have been enough for anyone? /s I don't see why shiny progress should be held up because you can't be arsed keeping up with new generations of tech. If you don't like it, go install a rom and some of the many many many alternate applications which keep sizes small. Mobile phones began, much like desktops began, extremely limited. We are simply seeing the same thing happen, we're now…

Installing a ROM is actually why it's unlikely that my next phone will be an HTC. I made the mistake of buying what was basically their flagship phone for a little while, which was promptly dumped for the HTC One.

Take a look at the ROM situation for the HTC Ruby platform, aka the Amaze, aka the only phone in its product line. Despite what Wikipedia says, there isn't a huge mass of aftermarket ROMs because the phone itself had such a relatively small distribution and was discontinued.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#143

Replaced by Chrome ("that giant hog"). I'm on a slightly older phone, but I actually removed Chrome from it not long ago. I started having problems with updating apps due to insufficient space, and while I have a fair amount of crap installed, I also have ~2.5GB of "Phone" storage for apps so I started investigating (this is separate from "sdcard" data storage which is ~8GB). Turns out Chrome, at least on the HTC Ama…

I guess I'm going to be forced to switch to Chrome now for safety's sake, but I've been avoiding it because it has some major usability problems that Android Browser doesn't. In particular, not reflowing a web page when you zoom in is infuriating because I invariably end up zooming in order to be able to read an article, then I have to pan side to side for every line of text. Font sizing is bizarre too. Web pages suddenly have font sizes increasing and decreasing seemingly at random, and to the point of illegibility. I just tried loading this page up on Chrome for Android and the header text (new | threads | comments ...) is absolutely microscopic.

I'm no browser snob -- I'm perfectly happy to use the stock AOSP browser even though it's got some stuff I don't like about it -- but I really can't understand how anybody uses Chrome for Android at all.

I suppose it's probably time to re-try-out some of the 3rd party browsers again.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#144
post #97

Earlier quoted context omitted.

You're not the only one. I'm sorry, but the Android issue has devolved into a holy war but... .. support is terrible on the Android side. Really terrible.

People need to stop buying terrible phones. Consumers keep rewarding companies who don't keep up with their promises and thus no one ends up giving a crap. In my opinion if you're not going to buy a Nexus device or a Moto E/G/X then you might as well buy Apple. The Android One program will hopefully add more to that.

You can only know if it is a "terrible" phone until long after you have bought it.

Most people don't have the ability to make an informed decision about a phones purchase (or they want to buy an iPhone or Nexus but they simply can't afford it).

I bought a Google Nexus at USD650 retail - a perfect counterexample to your advice.

I recommend iPhones to those who can afford it (purchase price, insurance, screen replacements etc.).

I recommend Huawei Y310/320/330 for those who don't have much.

In between there are too many other factors to make a straight recommendation (e.g. buy second hand iPhone versus a Moto G).

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#145
post #78

Earlier quoted context omitted.

Just switch to CyanogenMod or other custom compilation; there is a gain from Nexus brand in the ease of unlocking bootloader (;

I'm not convinced CyanogenMod (or any other variant) is actually that great; I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now. There have been a number of CVEs issued for Android (and likely numerous others cover Android as a platform, covering OpenSSL for example) over that time period, so there's no way the phone is anywhere near up-to-date with security fixe…

> I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now.

Same. The newest version which supports my phone is years old, and there are major usability issues, particularly in the dialler interface. The manufacturer (HTC) UI was miles better (i.e., actually usable).

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#147
post #97

Earlier quoted context omitted.

People need to stop buying terrible phones. Consumers keep rewarding companies who don't keep up with their promises and thus no one ends up giving a crap. In my opinion if you're not going to buy a Nexus device or a Moto E/G/X then you might as well buy Apple. The Android One program will hopefully add more to that.

You can only know if it is a "terrible" phone until long after you have bought it. Most people don't have the ability to make an informed decision about a phones purchase (or they want to buy an iPhone or Nexus but they simply can't afford it). I bought a Google Nexus at USD650 retail - a perfect counterexample to your advice. I recommend iPhones to those who can afford it (purchase price, insurance, screen replaceme…

My one year old Nexus 4 is on KitKat. I guess you're talking about the Galaxy Nexus. While I agree with you that they dropped the support a way too soon, being the reference phone you'll have no problems in updating it with CyanogenMod, which is a really good distribution btw.

But as a slight counterpoint, given the fast release cycle, you can't expect them to support a phone forever. You mentioned iPhones. Well I have an iPhone 3GS. It's a perfectly capable phone that still works and that was still sold as the low-price alternative after iPhone 4 happened, yet Apple stopped supporting it as well. But I can understand that, because these OSes get more bloated with stuff and it leads to a shitty experience. I was able to upgrade an older Galaxy S (first generation, shipped originally with 2.1) to 4.3 by means of CyanogenMod and it was unusable due to the less than capable hardware.

Google did drop the support too early for the Galaxy Nexus, but try out CyanogenMod. I'm even thinking of installing it on my Nexus 4 because the Android on this device is bloated with Google-stuff that I cannot uninstall and it pisses me off. It's also enlightening to install CyanogenMod without Google Play, for an all open-source experience ;-)

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#148
post #78

Earlier quoted context omitted.

Just switch to CyanogenMod or other custom compilation; there is a gain from Nexus brand in the ease of unlocking bootloader (;

I'm not convinced CyanogenMod (or any other variant) is actually that great; I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now. There have been a number of CVEs issued for Android (and likely numerous others cover Android as a platform, covering OpenSSL for example) over that time period, so there's no way the phone is anywhere near up-to-date with security fixe…

CyanogenMod changed their release versioning. There are no more "stable" builds anymore, at all. You're supposed to run "monthly" or "milestone" or whatever they are called. Yes, I think they could have communicated this much better.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#149

Earlier quoted context omitted.

The Galaxy Nexus was released only 3 years ago. Since when was that beyond the expected lifespan of a flagship product from one of the world's largest tech companies? Don't think I've ever owned anything with such a serious planned obscolence issue. Windows supports its OS releases for 12 years (and doesn't lock you in, so you can usually follow official upgrade procedure anyway). And anything "dumber" than a smartph…

Since when has anything over 2 years, for a phone, had support? Anything over that is the exception, not the rule. Apple has better support than most, but even their phones degrade with features missing on older phones AND included new features run like ass (every time my fiance upgrades old phone to new iOS she hate life until upgrade). A 2 year old phone really is ancient... much less three or four... Who actually…

But at least there is the choice with Apple. You don't have to upgrade, but if you want the new security fixes, you have them.

With Android, if you find a beloved phone by many, you will be supported for YEARS. My gTablet was being updated by the community for 4 years after the last official update. My Galaxy Note has nightlies from multiple different projects. My wife's Sony Xperia Arc S has consistent updates still. You find a phone that people fell in love with and you will have your updates until the hardware is dead.

Re: Major Android Bug Is a Privacy Disaster (CVE-2014-6041)

#150

Earlier quoted context omitted.

I'm not convinced CyanogenMod (or any other variant) is actually that great; I have a Samsung Galaxy S2 (i9100 model), the last non-nightly CyanogenMod update was over a year ago now. There have been a number of CVEs issued for Android (and likely numerous others cover Android as a platform, covering OpenSSL for example) over that time period, so there's no way the phone is anywhere near up-to-date with security fixe…

CyanogenMod changed their release versioning. There are no more "stable" builds anymore, at all. You're supposed to run "monthly" or "milestone" or whatever they are called. Yes, I think they could have communicated this much better.

And anyone running the stable builds have therefore never been updated to an at all recent build… sighs

And looking at my phone, I have no idea how I'm meant to update to the milestone builds. The updater lets me select "stable" or "all (inc. nightly)", and nowhere do the milestone builds appear…

None of this is helping me believe there's really any decent security story. Abandon all users who don't check the website (or whatever) to find out about releases, trusting the built-in updater to provide updates. Never publish any security advisories that cover your distribution…

Post reply on HN